2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38458 | HIGH | 8.8 | 0.9% | Jun 16, 2024 | Xenforo before 2.2.16 allows code injection. |
| CVE-2024-38457 | HIGH | 8.8 | 7.4% | Jun 16, 2024 | Xenforo before 2.2.16 allows CSRF. |
| CVE-2024-38454 | MEDIUM | 6.1 | 0.3% | Jun 16, 2024 | ExpressionEngine before 7.4.11 allows XSS. |
| CVE-2024-38448 | CRITICAL | 9.1 | 0.5% | Jun 16, 2024 | htags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell... |
| CVE-2024-38443 | MEDIUM | 6.2 | 0.2% | Jun 16, 2024 | C/sorting/binary_insertion_sort.c in The Algorithms - C through e5dad3f has a segmentation fault for deep recursion, whi... |
| CVE-2024-38441 | CRITICAL | 9.8 | 0.9% | Jun 16, 2024 | Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[len] to '... |
| CVE-2024-38440 | HIGH | 7.5 | 0.9% | Jun 16, 2024 | Netatalk before 3.2.1 has an off-by-one error, and resultant heap-based buffer overflow and segmentation violation, beca... |
| CVE-2024-38439 | CRITICAL | 9.8 | 0.9% | Jun 16, 2024 | Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[PASSWDLEN... |
| CVE-2024-36397 | MEDIUM | 6.1 | 0.3% | Jun 16, 2024 | Vantiva - MediaAccess DGA2232 v19.4 - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site S... |
| CVE-2024-38428 | CRITICAL | 9.1 | 0.7% | Jun 16, 2024 | url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be inse... |
| CVE-2024-38427 | HIGH | 8.8 | 0.5% | Jun 16, 2024 | In International Color Consortium DemoIccMAX before 85ce74e, a logic flaw in CIccTagXmlProfileSequenceId::ParseXml in Ic... |
| CVE-2024-38395 | CRITICAL | 9.8 | 1.5% | Jun 16, 2024 | In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution mi... |
| CVE-2024-38394 | MEDIUM | 4.3 | 0.3% | Jun 16, 2024 | Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kerne... |
| CVE-2024-6016 | CRITICAL | 9.8 | 0.5% | Jun 15, 2024 | A vulnerability, which was classified as critical, has been found in itsourcecode Online Laundry Management System 1.0. ... |
| CVE-2024-6015 | CRITICAL | 9.8 | 0.5% | Jun 15, 2024 | A vulnerability classified as critical was found in itsourcecode Online House Rental System 1.0. Affected by this vulner... |
| CVE-2024-6014 | CRITICAL | 9.8 | 0.5% | Jun 15, 2024 | A vulnerability classified as critical has been found in itsourcecode Document Management System 1.0. Affected is an unk... |
| CVE-2024-6013 | CRITICAL | 9.8 | 0.5% | Jun 15, 2024 | A vulnerability was found in itsourcecode Online Book Store 1.0. It has been rated as critical. This issue affects some ... |
| CVE-2024-6009 | CRITICAL | 9.8 | 0.5% | Jun 15, 2024 | A vulnerability has been found in itsourcecode Event Calendar 1.0 and classified as critical. Affected by this vulnerabi... |
| CVE-2024-6008 | HIGH | 8.8 | 0.5% | Jun 15, 2024 | A vulnerability, which was classified as critical, was found in itsourcecode Online Book Store up to 1.0. Affected is an... |
| CVE-2024-31870 | LOW | 3.3 | 0.2% | Jun 15, 2024 | IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enumeration by a local a... |
| CVE-2024-27275 | HIGH | 7.8 | 0.2% | Jun 15, 2024 | IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority req... |
| CVE-2024-6007 | CRITICAL | 9.8 | 0.6% | Jun 15, 2024 | A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects... |
| CVE-2024-6006 | LOW | 3.5 | 0.4% | Jun 15, 2024 | A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been rated as problematic. Affected by this iss... |
| CVE-2024-6005 | LOW | 3.5 | 0.4% | Jun 15, 2024 | A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been declared as problematic. Affected by this ... |
| CVE-2024-5611 | MEDIUM | 6.4 | 0.3% | Jun 15, 2024 | The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘label_years’ ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now